en
Back to the list

Ledger investigates potential wallet tampering after reports of $86 million in crypto stolen

source-logo  coindesk.com 1 h
image

Crypto hardware wallet maker Ledger said Friday it is investigating reports of stolen funds linked to devices sold through a reseller in Southeast Asia as a suspected $86 million heist threatens to add to the industry's mounting losses from exploits this year.

Pseudonymous blockchain investigator Specter said on X that more than $86 million in crypto may have been stolen from hundreds of wallets. There hasn’t been any independent confirmation of the amount of user assets affected.

Specter said they traced suspected theft addresses across Bitcoin, Ethereum and Tron after seeing reports from Ledger users on X and Reddit. It remains unclear whether the incidents are connected or what caused the losses.

Ledger acknowledged in the post the reports of missing funds from customers who purchased devices through CryptoBilis, a reseller in Southeast Asia, but did not confirm the reported loss amount or identify the cause.

As a precaution, the company said it asked CryptoBilis to pause all sales and shipments while its investigation continues. Ledger advised customers who purchased devices from the reseller within the past 90 days not to begin setting them up. Those who have already activated their wallets should consider moving their assets to a new Ledger device with a newly generated recovery phrase, the company said.

The potential theft may add to an already rough year for crypto security. Last month, crypto exchange Bitget suffered an exploit that resulted in over $350 million in stolen assets. Other major incidents included Liquid Network at about $320 million, Drift at $295 million and Kelp at $293 million, according to DefiLlama data.

In Ledger’s case, one possible explanation is a supply-chain attack, in which hardware wallets are tampered with before reaching customers. For example, an attacker could supply a device with a recovery phrase they already know, allowing them to access funds deposited into the wallet at a later date.

Such a scenario would differ from a breach of Ledger's own systems. However, there is no confirmation that device tampering or pre-generated recovery phrases caused the reported losses.

The incident remains under investigation, and it is unclear how many users were affected, whether the reported thefts are connected or how much cryptocurrency was lost.

app-logo

Know when your
coins move

Alerts, real-time prices, and market news — all in one app
4.8 based on 40K reviews in the App Store and Google Play
coindesk.com